Last updated: August 13, 2026
Said & Done
Privacy Policy
Apex Optimal LLC
1. What Stays on Your Device
Said & Done stores your working data in a database on your phone. We do not hold a copy and cannot read it. This includes:
- Invoices and estimates, including line items, labor, materials, and totals
- Client names and contact details you enter
- Job costs and expenses you log
- Mileage entries
- Running tax set-aside tallies and yearly summaries
- App settings and business details used on your invoices
Because this data lives on your device, it is included in your device backups (iCloud or Google) if you have those enabled. Those backups are governed by Apple’s and Google’s privacy policies, not ours. Deleting the app deletes this data from the device.
2. Voice Recordings and How They Are Processed
This is the part of the app that sends data off your device, so we want to be precise about it.
When you describe a job out loud, the app records audio and sends it to our processing service, which forwards it to OpenAI for two steps: speech-to-text transcription, and extraction of structured invoice fields (client, line items, amounts) from that text. The resulting fields are returned to your device and saved locally.
The recording and transcript pass through our service and are not stored on our servers. OpenAI processes the data as our service provider under its API terms; data submitted through the OpenAI API is not used to train its models.
Whatever you say while recording is included — so if you say a client’s name and address, that is part of what gets transcribed. If you would rather a detail never leave your device, do not say it out loud; type it into the invoice instead.
3. Payments
Said & Done can attach a Pay Now link to an invoice. Those payments are processed by Stripe through a Stripe account connected to your business.
- Your customer’s card details are entered on Stripe’s pages, never in our app, and we never see or store them.
- Funds settle into your own Stripe account. We do not hold, route, or take a cut of your money.
- To connect your account, Stripe collects identity and business details directly from you for its own compliance obligations, under Stripe’s privacy policy.
4. Subscriptions
If Said & Done offers a paid tier, purchases are made through the Apple App Store or Google Play and managed with RevenueCat, which records the status of your subscription and an anonymous identifier so the app knows what to unlock. We do not receive your card number from the app stores.
5. Your Clients’ Information
Said & Done is a tool you use to bill your own customers, so you will be putting other people’s details into it — names, addresses, phone numbers, email addresses, and what work was done for them.
That information is yours and stays on your device. You decide what to collect and how long to keep it, and you are responsible for handling it lawfully. In data protection terms, you are the controller of your clients’ data and we act as a processor only for the voice step described in section 2.
6. Third Parties We Use
- OpenAI — transcription of voice recordings and extraction of invoice fields.
- Supabase — hosts the service that passes recordings to OpenAI and issues payment links.
- OpenStreetMap (Nominatim) — turns your shop address and a job address into coordinates so the miles between them can be estimated. Handling this off the device is the reason the app never asks for location access.
- Stripe — card payment processing and payouts to your account.
- RevenueCat — subscription status.
- Apple / Google — app distribution, in-app purchases, and device backups, under their own policies.
We do not sell your personal information, we do not share it with advertisers, and the app contains no advertising or third-party analytics trackers.
Where this data goes. These providers are based in the United States, so if you use Said & Done from the EEA or the UK, the limited data described above is transferred there. We rely on the European Commission’s Standard Contractual Clauses, and the UK Addendum where it applies, as the legal basis for those transfers. We share only what a provider needs to do its job, and each acts as our processor or as an independent controller under its own policy.
7. Data Retention
Your invoices and business records are kept on your device for as long as you keep them; you control deletion from within the app. Voice recordings and transcripts are not retained by us after the invoice fields are returned. The same is true of the other two things that leave your phone: the addresses sent to estimate mileage, and the amount and job description sent to create a payment link. We keep neither once the result comes back — OpenStreetMap and Stripe handle them under their own policies. Stripe and the app stores retain transaction records for the periods their own policies and legal obligations require.
8. Your Rights
Because your records live on your device, you already have direct access to your data: you can view, correct, export, and delete it in the app at any time.
If you are in the EEA or UK, the GDPR gives you rights of access, rectification, erasure, restriction, portability, and objection. If you are a California resident, the CCPA gives you rights to know, delete, correct, and opt out of sale or sharing — we do not sell or share personal information as those terms are defined. To exercise any right that involves us rather than your own device, contact us at hello@apexoptimal.dev. We will not discriminate against you for exercising these rights.
9. Children
Said & Done is a tool for running a business and is not directed at children. We do not knowingly collect personal information from anyone under 13 (or under 16 in the EEA and UK). If you believe a child has provided us information, contact us and we will delete it.
10. Security
Data sent for voice processing and payments travels over encrypted connections. Data on your device is protected by your device’s own security — a passcode, Face ID, or fingerprint lock is the single most effective thing you can do to protect your invoices and your clients’ details. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
If a breach affecting your personal information does occur, we will notify the relevant supervisory authority within 72 hours of becoming aware of it where the law requires, and we will tell you directly and without undue delay if the breach is likely to put your rights or your clients’ information at risk.
11. Changes to This Policy
If we change how the app handles your data, we will update this page and the date at the top. Material changes will be communicated in the app or by email before they take effect.
12. Contact
Apex Optimal LLC — hello@apexoptimal.dev. The person who answers is the person who wrote the app.